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TOP OECRCT//CQMINT/mOrORN 
NATIONAL SECURITY AGENCY 
CENTRAL SECURITY SERVICE 

FORT GEORGE G. MEADE, MARYLAND 207SG-0000 

18 February 2010 
MEMORANDUM FOR THE CHAIRMAN, INTELLIGENCE OVERSIGHT BOARD 

THRU: Assistant to the Secretary of Defense (Intelligence Oversight) 

SUBJECT: (U/ /FOUO) Report to the Intelligence Oversight Board on NSA Activities - 
INFORMATION MEMORANDUM 

(U//FOUO) Except as previously reported to you or the President, or otherwise stated in 
the enclosure, we have no reason to believe that any intelligence activities of the National Security 
Agency during the quarter ending 30 June 2009 were unlawful or contrary to Executive Order or 
Presidential Directive and thus should have been reported pursuant to Section 1.6(c) of Executive 
Order 12333. 

(U/ /COUO)~ The Inspector General and the General Counsel continue to exercise oversight 
of Agency activities by inspections, surveys, training, review of directives and guidelines, and 
advice and counsel. These activities and other data requested by the Board or members of the staff 
of the Assistant to the Secretary of Defense (Intelligence Oversight) are described in the enclosure. 



r a nn ' 


GEORC^f ELLARD 
^.Inspector General 

PATRICK J. R 
Acting General Couni 



(U//TOUO) I concur in the report of the Inspector General and the General Counsel and 
hereby make it our combined report. 




LEITH B. ALE) 

Lieutenant General, U.'S. Army 
Director, NSA/Chief, CSS 


Enel: 

Quarterly Report 

This document may be declassified and marked 
‘UNCLASSIFIED/, ^Fiar Offi trial I'ou Only” 
upon removal of enclosures) 


TOP SECRET//CONONT//NOFORN 


Approved for Release bv NSA on 12-19-2014. FQIA Case # 70809 (Litigation)! 
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'■'Mi) 

|b)(3)-P.L. 86-36 


1. (U// FQUO) Intelligence, counterintelligence, and intelligence-related activities 
that violate law, regulation, or policy substantiated during the quarter, as well as 
actions taken as a result of the violations 


(l ) Intelligence Activities 

iTli >.il VRLI TO i'HA. I VI Vi Unintentional collection against United States persons 

This quarter, there wer e| [ instances in which "Signals Intelligence (SJGfNI) analysts U 
inadvertently targeted or collected communications to. from, or about U.S. persons whiles 
pursuing foreign intelligence tasking. All intercepts and reports have been deleted or destroyed 
as required bv United Stales S1GIN.T Directive{I SSil) SP0018 


(U) Unauthorized Targeting 

-f- DTTll//>if j A National Security Agency (NS A) analyst discov ere d I that 

Electronic Mail u ...atn ., ele ctor remained tasked after an Attorney Ck oral mitK lN Aoi uiaq 
expired on 1 Ire 'NSA analysi detasked all selectors onT before 


expired on 1 he NSA analy st detasked all selectors on| 

the author ization expired, hut was not aware_ 

_The unauthorized targeting took place from 

when Foreign Intelligence Surveillance Act (f I SA) Amendments Act (P7v~ 

was obtained. No collection occurred between 

the incident resulted in a change in operating procedures. 


authorization 
A rev lew of 


the NSA database 


JSA, F Vl ¥ ~)-A software updat e caused a I _failure in one 

— Iresulting in collection of between 

_ Theol d vc, n l the 3 wa e was reloaded, and the 

was rebuilt to co rrect the problem. The collection was purged from 


human error caused 


I | The mistake was found and corrected!_ \ 

NSA -'Attorney General-approved minimization procedures do not permit. NSA to use I ,S. 
k rson identifiers as selection terms in repositories of collected communications.; It is unknown / 
how m uch, or even if. unauthorized data was collected, and it is not possible to sort the 

i res ults front valid foreign intelligence targeting results or purge the data by tvh ;ncmg the 
1 .S. person selector w ithout further Executive Order (E.O.) 1-2.333 violations. 

(1 yb/yl/tMf) _selectors belo nging to a U.S. 

person were retasked b> mistake.. The telephone selectors had been detasked 
." ben NSA gnah sts learned of the target's 1 kS. citizenship, but the rfetaskif x; ■ [ys 1 Trio 

I _Consequently, the selectors were retaskecl_ 

intercepts'were collected. 1 he selectors v ere detasked and appropriately- marked'to 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-P.L. 86-36 


(b)(1) 

(b)(3)-P.L. 86-36 


Derived from: NS \ GSSM 1-52 
Dated: 20070108 
DeclawiIv On: NDOMOK 
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mn 

(b)(3)-P L. 66-36 


(b)(1) 

(b)(3)-P.L. 86-36 


TOP ShCRK'D/COMINl NOl - ORN 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-18 USC 798 
(b)(3)-P.L. 86-36 


prevent tasking, and the related collection, was purged from the NSA'database 
No reportswere issued. 


; 1 iuman error result ed in the targeting of 
was in the United States between 


while he 
The NS A a nah st learned of 
hut forgot to 


.detask the selector On 


tar get had been i n the United States sineel 
on with no collection noted 


Jthe ymaivst learned frnm rollatei .il mleliige.nce that the 

tor was detasked 


Jetw ceil 


I rom collateral Intel 

The targeted .select 


(T9//SI//NF) On 


an NSA analvst authorized to conduct Communications Securit y 


(COMSEC) Monitoring operations identified possible criminal activity of child abuse. After the 
discovery had been reported, the analyst incorrectly reviewed other collection from the l .S. 
person looking for more e vidence of child abuse. The analy st was not authorized to search the 
COMSEC data for a purpose unrelated to C( )MSf C . (bj( 3 )- 5 o use 3024 (i) 

(b)(3)-P.L. 86-36 


selector was removed from tasking 


l he two analysts responsible tor monitoring 

|the target were on leave when 

the target entered l '.S. territorial waters on| \ 1 lie s 

elector was removed from 

collection on 

No collection occurred w hile the v essel was in C.S. waters. No 


reports were issue d. As a result oi this process weakness, additional analysts were added to Die 
■to'prevent future oversights. 


. (SV/'SE ' IMFT while reviewing skills learned in a database training class, an NSA 

analyst queried the personal e-mail address he shares \\ 1th his wife. 1 he analyst explained that 
1 e used the familiar e-mail address because a query for target Selector data did not produce 
results, and he was concerned that he was not formatting the query proper!). 1 his violation was 
found by the analyst’s auditor! No collection resulted from the mistake. The 


analyst reviewed 1 SSID SPOOI8 and completed additional database training. 


(TH/.'SU. REL TO USA. FVKY) [^ 
the I 'oiled Slates on 


m NSA analyst found that a targeted selector 
his was d iscovered during a Department 
he selector was detasked on 


-of-Justice direc ted audit of 

No collection or reporting occurred while the target was in the l nited States. 



i UP M CHIN ■ 'CUMIN') -'NOfOKt r 

1 


(b)(3)~18 USC 798 
(b)(3)-P.L. 86-36 
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(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-P.L. 86-36 


fbXD . . 

(b)0)-P.L. 86-36:': 


rii^|_selector was jeiasked on | 

queries were made on the selector from! 
target was in the United States, 


-^'Chiring ; lectorreview 


i 

lie an h SA analyst found the mistake.. No 
and no reports were issued while the 


INS \ analysts focrodl 


(b)(1) 

(b)(3)-P,L 


The selector vVas detasked l and | :: .f reiated intercepts were purged from 

an N SA database the same day. Additionally. NSA analysts iquik | ~| seleetors also tasked 

since! _remained on-taski ng aft er the target entered the United States in f 

_ The selec tors were detasked, anri f i ntercepts were purged from an s'SA database on 

_No reporting resulted from the collection, t he risk of recurrence has been 

reduced through changes in the detanking notification process. No reports were isst on 1 lie 
intercepts.. 


( I S >;i Nb) An NS A analyst Jailed lo check a target's f ,S, person statu s prior to tasking. 

selector s were taske d:_____The ana list found his 

mistake | while conducting target research’ All_selectors v ere detasked on 

_and the resulting collection was purged from an \S \ database. No i eports were 

issued on the collection. 


(b)(1), 

(b)(3)-50 USC 3024(i) 
(b)(3)-18 USC 798 
(b)(3)-P.L. 86-36 



JNSA analysts found that a valid forcien target's selector was 


1 he selector was detasked 


| A database check re\ mlednoi illeeti m. and io reporting'ocetarred on the 
U.S. telephone number. 

/(b)(1) 

(b)(3)-50 USC 3024(i) 

(U) Database Queries (b)(3)-p.L. 86-36 


fed) ;; 

(b)(3)-P.L. 86-36 


(1 1 /AI/iNR < ) nl tccasions. anah sts eonstruct mJ poor database queries that targeted l S. 
persons, and onl I of those occasions, the queries returned results from the database, the 
returned results from the overly broad or incomplete queries were deleted, and no reports were 
issued. Procedural errors CO rtrih.ilgd to|~} T the| jviolatioflS. 

■ i IV/Si/iNi o an ; ». i a val vst gueri j v h he believ ed to be a foreign 

’ hh i^.d.wd in ^v.ihciion i| foreign intelligence 

indicated that and the analyst queried the selector w ithout 

confirming! - ^ 1 The analyst's auditor found the mistakeT" 


(b)(1) 

(b)(3)-18 USC 798 
(b)(3)-P.L. 86-36 


3 
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'(65(1 > 

(b)(3)-P.L. 86-36 


(b)(1)'. 

(b)(3)-P.L. 86-36 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-P.L. 86-36 


(b)C/ 

(b.(3)-P L. 86-36 


m? si ( Ri t ( om i\ i \o; ur\ 


2009. and the related collection was purged from the NS A database 
reporting occurred from the collection. 


'/(b)(1) 

/ (b)(3)-50 USC 3024(i) 
/ (b)(3)-P.L. 86-36 


No 


{i S. SI/ Nr-rOn 


an NSA Signals Development analyst queried 




in an effort to obtain 


forcig n intelligence targets. 


Pht] [resui is obtained were deleted £ 


he violation w as found by the analyst's ; 


and the analyst was 

counseled on unauthorized searches. No reporting occurred from the collection. 



N+riOtl 


an analy si fai 

Query 



the query did not 


while pursuing, a target related to the 


prior to cone 

kvas located in the United States. Found by an auditor! 


tuning a 


ITS . SI \1 > O n 


an NSA analyst queried a list of selectors not related to 


his cur rent n 
office. 


lice's mission. He had used the list during a previous assignment in another 


Jofthe selectors were found to be i n the United States. No collection resulted 
from the query, 7 he selector list was destroyer 


mffli//NF)o a 


while pursuing a target related to a 


an NSA analyst failed n 


query;. 


prior to conducting a 


Kvas located in the United States. Found bv the analyst's auditor 


the query arid results were deleted from the NSA database 


No reports were issued on the query results, and the analy st was counseled on due 


diligence. 


i 1 S SI Rl.l. m USA. TVCY1 an NSA analyst used the 



with no other/ 

qualifiers^ 

the analyst realized her mistake when the query returned 

approximately 

esults, The results were deleted without review 




(TNUBhTNH -On 

deuiski '. 1. ,kt 11 ,i to the analy a. the target selector! id been detasked when it was / 


kin NS A analyst queried a target selector after it had been 


deleted the resulting collection 
collection. 


|the 1 Inited States. When the analy st learned of the incident, he 

No reports were issued oh the 


hitman etror resulted in the targeting ot | | U .S. telephone 
I The NSA analy st forgot that line database 


-*- 4* -' H Nt i 

numbers related to a foreign 

hi queried contained unminj.tnized and u neyalu d SRdNT data. No collection resulted 
from the| [queries, which were deleted 




an NSA analyst perfor med a database query on a U.S. e -¬ 


mail address while researching a valid foreign target. 


he mistake was found by the analyst's" auditor on 


iOPShURb i ■rOMINl/v.NOl UltN - 
4 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-18 USC 798 
(b)(3)-P.L. 86-36 
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rop s k: kh i/ 1 t uuim \ui ■ o rn 


(b)(1) 

(b)(3)-P.L. 86-36 


and the query results were deleted 


The auditor provided 


additional query training to the analyst. No reports were issued. 


tTG ill N 4-t Unintentional dissemination of U.S. identities The NSA Enterprise issued 
| SItjINT product reports during this quarter. In tl ese reports. SKIIN' f analv ts 


improperly disseminated communications to. from, or about I If . S. persons or entities while._. 

pursuing foreign intelligence. All data h ave been deleted or destroy ed as required. A total of]_| 

S1GINT products were cancelled as NSA" - 


] analysts learned of the U.S. 


persons, organizations, or entities. The reports were either not reissued or were reissued with 
proper minimization. 


(U) The Foreign Intelligence Surveillance Act (FISA) 


(b)(3)-P.L. 86-36 


(U) Unintentional Access 



(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-18 USC 798 
(b)(3)-P.L. 86-36 


I UP S i ( Kl I t t >Mlh I ■ ■ NOi URN 
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(b)d: 

(b)(3)-50 USC 3024(i) 
(b)(3)-P.L. 86-36 


(U) Unauthorized Targeting 

■(Tft'TiF/NPt'l argeting continued on a I 1S( -aut horized target's e-mail selector after 

__ An NSA analyst noticed the lack of collection" 

on_ Research revealed the target_ 

The selector was removed from collection on No collection or reporting 

occurred. 

(TS//S 1NN.F) An NSA anal} st misinterpreted the provisions of a FISC Order and initiated _ 

targeting of cellular telephone numbers that were not specified on the Order. 


(b):f) 

(b)(3)-P.L. 86-36 


'.electors \vc 
NSA purged 


as the mistakes were idenlified. 


intercepts from the NSA database. 


1 1 S ' SI NT) (>n NSA learned that a HSC-approwd selector had not been remov e d 

from collection when the target _ 

| The 

S elector w as detasked and all related tolk ction was purged from NSA databases 

the same day. No reporting resulted from the unauthorized collection. (b)(1) 


(U) Database Queries 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-18 USC 798 
(b)(3)-P.L. 86-36 


(TS/dS - l/Ni - Ft l _ an NSA analyst queried non-FI SA datal 

Fhe-mistake was. found by the analyst’s auditor_ 

unai'tl >rized collection was not review ed aud deleted from the qm r re*. %[ 
No reporting occurred on the non-FISA data. 


(b)(1) 

(b)(3)-P.L. 86-36- 


■ (1. . . .NSA ..analysts queried non-FISA data ~| 

The analysts copied the wrong e-mail sele ctor into t teir query . 

. .error was found the s ame d.r to ‘he an ah st's auditor,".!ml 

mistake was discov ered by the analyst All associated results were deleted on 

when the mistakes were identified. No reports were issued on the non-FISA 

data. 


(1 >» >■! M -l _ _ an NS A analyst queried non-FIS A data 

The analyst di d not [ when crafting 

the query. The query results were deleted] when the errors were 

identified. No reports were issued on the non-FISA data. 

(i S- SI M ) H uman error resulted in the Kireetiiie oi_selectors_ 


(b)(3)-P.L. 86-36 


_ |an NSA analyst mistaken!. ■ levied an option_ 

_The mistake was noticed by the analyst corrected 

assoc> 1 with the unauthorized collection '', ere deleted 
issued on that data. 


The results 
and no reports were 


(b)(1) 

(b)(3)-P.L. 86-36 


















DOCID: 4165580 


_ In all instances, the calls were delete d immediately upon/ 

recognition, in accordance with 1 SSIL) SP0018 guidelines, and no reports were issued. 


Records Order 


(U) Nothing to report. 


(b)(3)-P I 86-36 


£■) Pen Register/Trap and Trace Order 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-18 USC 798 
(b)(3)-P.L. 86-36 


(I ) Nothing to report. 

(( ) The Protect America Act (PAA) 


•During a.tasking record review 


analysts found that an incorrect 


target selector. 


1 he incorrect selector was del aske d 

anaivsts do not know it me incorrect selector is a valid e-mail address. No collection resulted 


from the typing error. No reports were issued. 


(U) The FISA Amendments Act (FAA) 
(U) Section 702 


(U) Tasked under an incorrect FAA Certification 


"(b)(1) 

(b)(3)-P.L. 86-36 


i . IS hi Ul'.l. TO USA. FVEY) _ . an NS A analyst discove red that selectors 

associated w ith a valid foreign, t arget had been incorrectly tasked under the 

Certification Because there w as insufficient information to link the targets to 

the selectors were remov ed from tasking and 
the associated collection was purged from the NSA database. 

(I S ; . SI/VREL > 1 %V TV I ¥v an NSA anal} st discov ered that a selector had 

been tasked tinder two authorit ies- 1'he tar get selector was ■■inc orrectly tasked under th e / 

( ,cs1illcatioti[ | Instead of replacing the | | 

Certification wimihe corrected ITcrtilleation, the Lerlilicaiioxi 

was added. I h^ Ce rtifica tion was removed trom the tasking information | 

and collection under the! |Ccn ideation wa s purged from NSA databases 


(b)(1) 

(b)(3)-P.L. 86-36 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-P.L. 86-36 


7 
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, UP ShCR) i ,, i ( ) V1IN 4 N()| () | .’,\ 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-P.L. 86-36 


(U) Detasking Delay 

(h f 'Sicilia. 1U 1 <SA, FVEY) A n NSA analyst Ji d n i betas j larger selector when the 
target entered the l fnited Stat es on _ ©vei l _linterce vrs were purged from if e 


NSA database without review 
counseled on detasking procei 

(U) Section 704 

(IJ ) U.S Person Status 


tv 


ures. 


ten the mistake was identified. 1 he analvsi w us 


fb)(1) 

, (b)(3) P L. 86-36 


(TS//Sl/.^Nrt On two occasions, not all selectors were detasked when NSA analysts learned 
that an 1 \A Section 704 target was in the 1 mi ted Sta les. ..in the first instance, when an 
inexperienced NSA analyst lear ned on| 


the analyst mistakenly removed 
related collection occurred between 


and 


hat a .t arget -was in the f!ruled States, 

from taski nu the same day. No FAA- 
""]when the target was in lire 


databases 

_ 1. 1 rv c? ^ 1 1 ■: 

As a result of this violation, the mission area 

amended analytic training torerah .tasking and del, skiing proeet 

lures. The branch also 

knplcraentedp 


] The second instance 

occurred | when another analyst deiasked selectors 



vvas discovered and 

terminated 

and the resulting collection was purged irorri the NSA database the 


same day. No reporting resulted from either violation. 

(U) Section 705b 

(U) Unauthorized targeting 
fTS>7Sl//>«r: 


_|an NSA analyst mistakenly queried a selector while the target 

was in the United States . The tamet authorized for overseas collection under FAA section 705b. 
was in the United States| 


unauthorized target!ng. 
(U) Database Queries 


No collection or reporting resulted from tire 


-t TS//SI/.'Nrj 


[ 


an NSA analy st constructed a poor database query, which 

I. 'I he analy st had 


..•been usiife unfamiliar analysis tools as she was nursuinu a FAA 705b-authorized target. The 


query 

by the analyst's audited 


and the query results were deleted 


-(TS/AT'NFt 


an NSA analyst mistakenly queried PAA data while pursuing a 
FAA 705b-a ut horized targe t. Her mistake was compounded when she searched time frames 


preceding thv| 


authorization. The query 


intercepts were destroyed 


(b)(1) 

(b)(3)-P.L. 86-36 


- TO - p - sEeRgF^eeM fm 
8 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-18 USC 798 
(b)(3)-P.L. 86-36 
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tXb)(1) 

I(b)(3)-P.L. 86-36 


issued 


lwhentfie viola tit n wa: identified fctj the anaih si's auditor. J$o reports were 


(b)(1) 

(b)(3)-P.L. 86-36 


(T't'V's! ,r NF)| _Jan NSA analyst mistakenly qu erik u y latabase 11 rdata outside 

the authoris ation daw. .1 ho 1 r Q5ja authorization was granted o n£ ;// . I Data queries tor 

dates before_were not a uthorized. Queries on //Itareeted sele ctors were 

conducted to obtain target data between No data was 

obtained from the query. 


(U) Unauthorized Targeting 


t * fr l/'NT4 NSA anah Ms left a target' 


telephon e selectors on collection white 

I NSA anah sis were notified b\ the 
U.S. person in 


NSA analysts should have 


to collection occurred between 


(U) Detasking Delays 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-P.L. 86-36 


(TS//SI//NF) H uman error caused- 1 {_Jdetasking delay, w hich result ed ina lec ion while 

the target was in (he 1 nile'd States he : IA truh s i learned^_(hatthe target 

I'.lic 1 nitc J State-- ] } 1 he anah st detasked the target's telephone 

-selectors on l , _11 his oversight 

was : ur Ion! _The resulting collection, was purged from \NA databases on 

No reports were issued from that collection. 

(TS-SlftNpH V target selector remained on. collection _ after an NSA an alyst learned 

that the selector was not associated with the intended target.- ! the request to 

detask the target sel ector was overlook .a by the analyst responsible for the detasking. This e rror 

was brought to light _ whe n the e-mail sele ctor, tasked under the FAA j | 

Certificatio n.! the United States The selector was 

detasked or | and the data was purged from NSA databases on_ 

2009. i he delay between recognition of the v iolation and detasking and purging action occurred 
because the..anah st responsible for the action was on leave. 


tec 

(b)(3)-P.L. 86-36 


4 - rS/, ; Sl ' '7NiT I '-Qij_ Ian NSA analyst learned that a tarneted sele ctor remained tasked 

| alier the seleetoi_The analyst: 

re sponsible lo r detasking was on leave when the initial detaskin a notification was submitted on 

1 1 ■ angdffst was hotilied a gaip_whe n the selector was attain 

i. he seiector was detasked ( the data 

was purged from NSA databases] No reports were 

issued from the collection. 


ot all the selectors were detasked 


United States oft 


telephone numbers associated with) the 


nvuvrr 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-18 USC 798 
(b)(3)-P.L. 86-36 
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1UU SI i HI I. ( n\1i\ I \nl URN 


.(b)(1) 

::)(3) P.L. 86-36 


targe! w ere uei "a •’ beca use of an analyst's oversight. fhq 
detaske d on | 


selectors were 


and resulting collection was purged from NSA databases 


No reporting occurred From the uninientional cdlleetion. 


4 ] ■ ■ si \pt 


the United States on 


“Jrh 


NS A analysts learned that a target selector 
I but the selector was not detasked unti l 


intercepts were purged from NSA database- on 


(I I) Destruction Delay 


(b)(1) 

(b)(3)-P.L. 86-36 


(TSOSb/NT) I US. person data was not purged ti 


NSA databases in a 


ay manner. 


Collectio n obtained while an b.AA target was in the Unite d Suite w ‘.purged 


after NS A analysts learned that the e-mail selecton 


data was purged 
t .S. location. 


The 

Ithe 


purging occurred. 

No reports w ere issued. 


and because of staffing shortfalls, a hack Ion ior 


(b;n 

(b)(3)-5£> USC 3024(i) 
(b)(3)-P.L. 8C-3C 


ST i n. ’ "B\ target tasked under 1 \ qCertification 


the 11 piled Stales for 


before a request to purge NSA dal abases o f collection was obtained, 
the target’s e-mail selector 

N I I 


''submitted! 


!_! The request to purge the d ata was 

Purging, comme nced immediately and was completed ! 


purgin g occurred; 


and because of staffing shortfalls, a backlog for 


No repoi 1 .eiTissued. 


(b)(1) 

(b)(3)-P.L. 86-36 


after NSA 
when an 


( I S . SI /NFt-A targeted selector remained on tasking 
analysts learned that the target was a IAS. Green Card holder. 

NSA analys t, learned of the 1 US , person status, he submitted a detasking request on the selector. 
Action was not taken on the detasking request. This mistake was compounded by delays in 


purgingjhc data from NSA databases. Data was not purged from 

latter NSA analysts learned of the targets US'. 


(B)(1).. 

(b)(3)-P.L 86-36 


person status. 


- tilS db i U Ni.ii j 
analyst learned on 
After the selector was detasked| 

NSA database was not completed until 
because of staffing shortfalls, a backlog for 


delay in purging data from a NSA dat abase occurred after an NS.A 


that a targeted e-mail selector 


the 1 niled States. 


faction to complete purging of the data from the 

and 


purging occurred. 


No reports were issued. 


Ivhen the 


the United States-on) 


(INUTii ’'NT) A foreign target's sel ector was not detaske d an 
authori sation expired. The se!ect ot |~ 

analvsl| _ | .t dr> . U ~t hut UN .1 to-Jeta.sk it.. Conscqucntf . the 

when FAA tasking was enacted. The 


i be 


selector 


sc lector was detasked 


(b)(1) 

(b)(3)-P.L. 86-36 


- t - t)f OLClti I t i t.MIN 1 . N( fiditN 

10 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-P.L. 86-36 
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(b)(1) 

(b)(3)-P.L. 86-36 


(U) Dissemination 

(T S //SI//NF) On 24 June 2009. during She end-to-end review of the FISA Bum ness Record (RR) 
Order implementation. the review team found that NS A disseminated one SKII N' I pro duct report 
in a manner not authorized bv the FISA RR Court Order. Five report, containing_F.s. 


;pct>- was lorwan 


At the request of NSA, 


purged the data from its 


I'cbosIRVios 


(U) Other 


fl i) Unauthorized Access 


tb)(3)-P.L. 86-36 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-P.L. 86-36 


-ff 4 ] "SICMFC _ , " _analyst working in the NSA_ 

was permitted access]to unminimized SK IIN' j and U.S. person data for 
almost two years with training credentials (bat had been allowed to lapse by his organization. 

The security violation was compounded when NSA did not confirm- the analyst’s training before 
allowing him access to unmimmized SKTIN T. j Frnployees.vvith access to u nmii imizc 1 SIG1N ! 
data are to successfully complete l SS!D SP001B training bi-annualh. fhe 
I'SSID SPOO18 training was two war-, out of s cope. ! he analyst's access to u"nrrimt zed 
SIG1NT data was terminated I when the; overs) ph t was identified by atl | | 

Staff Officer. J he analyst returned to the 


®(fi.. 

(b)(3)-P.L. 86-36 


t'l fi- -'fdi'VNf. NSA technology developers a nd analysts working witlj _ 

accessed a shared metadata database account from_in 

violation of NSA C SS Manual 130-1, NSA 1 CSS Operational Information Systems Security 
Manual. The discovers was made by a database manager who q uestioned the runniim time of a 
query while monitoring the data system, The database contained- which | ~| 

of the users were not authorized to access. Several procedures were not followed properly, 
leading to the access of unminimized and unevaluated data, including FISA data, without 
appropriate'database access authorizations or database oversight requirements. First, the project 
activ ities had not been vetted through the NSA Office of t ienerai (. ounsel. Second, compliance 
adv ice from NSA SIOIN I 1 JireetoratcN Oversight and Compliance had not been sought, ihial. 

some employees had not completed training necessary fo r data hand line. < )l the | _ 

employees| ]had not completed tra ining for han dling_data, andf afthe | | 

had not completed training for handling data. The divisi on chief misunderstood that 

access to the d ata was permitted upon submis sion of access requests.! __ 

metadata were purged from the 


(1>I vfil - 'RF - TO FA A - PVEY| __|ah NSA analy st forwarded ; Po yerP< int slide 

containing unmini mized SIOIN'T from F.O 12333 collection to I 

_recipients befot the slide was reviewed'and rev ised by the| 

_Branch. The PowerPoint slide was part of an integrate.! vn-nbF - nTT 7“ 

multi-media report and did not contain U.S,person information. When.the analyst saw that the 


(b)(3)-P.L. 86-36 
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Mi) 

;b)(3)-P.L. 86-36 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-18 USC 798 

i UP M( i d I ( )\l ! \l M.tlURN (b)(3)-P.L. 86-36 


(b)(3)-P L 86-36 


b ct of (lie report had been released lie assumed that th« slide < ould be disseminated) All f | 
recipients confirmed deletion of the PowerPoint slide. 


1 FS"S1 Pl-T. TO USA. FULA- 


An NS A 

li 

spreadsheet containing I- ,\A da 

(a to an. NS A 




incorrectly fofyVarded a 
who had not been 


cleared for FAAdata. 


The access violation was compounded when the_pi> I not notice the FA A data 


mad been 

1 


handling caveat anddurt.her disseminated (he spreadsheet toothers within th e SIG INI Production 
Chain by e-mail. An analyst recog nized the handling caveat and notified ihe | | oftlie improper 
disseminations._recipients not authorized access to FAA data confirmed 


deletion of the e-mail. 

( IS SI Rl.l TO USA. FVEY) 


to another cryptanalystf 


an NS A cryptanalyst showed FAA data 
1 he other cryptanalyst was not cleared 
for FAA data. When the cryptanalyst realized, that the content was derived from FAA collection, 
he removed the data from his computer screen 


(IJ) Computer Network Exploitation (CNE) 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-P.L. 86-36 



(F FI Hid i(i UFA. FVHY) 


-r ' FI m i rn USA. i. VIA. 


BIG1NT intercept 



While re\ ievvinJl |a t s. e 

information 



|a t i.ts. analyst noticed, u.s. person 


(S Itfi •'! (■ ) USA. FVi 


FAA data to recipients 


S3 


an NS A analyst forwarded an e-mail containing 


_at whom had not completed trai ning re quired for access to FAA 

mtoniiatioh. Within one hour of recognizing the mistake. the||"~ — | >< > not authorized’ 

access to FAA data had deleted the e-matl. 


(b)(1) 

(b)(3)-P.L. 86-36 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-P.L. 86-36 


1 OP fi EC R1 - 1 ( ()M!\ 1 /. NO F URN 
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i up mxmri - (omim xo i orx 


(l i Counterintelligence Activities 

(LJ) Nothing to report, 

(U) Intelligence-related Activities 


■ (b)(1) 

;b)(3)-50 use 3024(i) 
(b)(3)-P.L. 86-36 


(S//SI//NF) To reduce the risk of unauthorized telephony collection and prevent viol ations. N SA 
instituted a process to give analysts greater and taster insight into a target's location.__ 


In the 


nstanees v hen collection \ 


occurred, it was purged frdm N 

SA databases. 


(IS Ail .M i 



NSA analysts t'ounc 

e-mail selectors 



on!\l 


1 1,1 


Collection occurred in 


instances and was purged from NS.\ databases. 


(C//.R.EL TO U^ A, g¥ E¥) -Although not violations of T.U, 12333 and related directives, 
NSA/CSS repot; \ i nstances in- u hieh database, access was not terminated when aceews w as 
no longer required. Once identified, the accesses were terminated. 


(b)(1) 

(b)(3)-P.L. 86-36 



(C/ZSICREL TO USA, i VTV) While developing a brief to present to the 


in 


containing data n$t rels asable to foreign nationals (NOFORN). Research 


revealed that one of the four gi 

raphical user interface (GUI ( tooli 

(the GUI. This 

seeurit\ matter occurred 


and was discovered in an auditor 


he GUI authentication access was corrected 


it 


tained by the analyst. // 


No NOFORN data was 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-18 USC 798 
(b)(3)-P.L. 86-36 


(b)(3)-P.L. 86-36 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-P.L. 86-36 
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TOP SECROT"COMIN ly/NOTOKN 


2. (U/ /r0U0 t NSA Office of the Inspector General Intelligence Oversight 
Inspections, Investigations, and Special Studies 


(T/ TFOUQ) During this quarter, the OIG reviewed various intelligence activities of the 
NSA 'CSS to determine whether they had been conducted in accordance with statutes, executive 
Orders. Attorney General procedures, and Department of Defense and internal directives. With 
few exceptions, the problems uncovered were routine and showed that operating elements 
understand the restrictions on NSA/CSS activities. 


(U I <>C (AtNSA/CSS Texas (NSAT) 


(h)(i) 

(b)(3)-50 USC 3024(i) 
(b)(3) P L 86-36 


{U/ /FOUO) J oint IG inspectors examined intelligence oversight (I/O) program management, I/O 
training. I/O knowledge, and application of l/(), Despite fragmented oversight oj TO training, 
NSAT operates well in the application of the NSA authorities. The recently appointed 10 
Program Manager is well known and has begun to make improvements to the site's I/O \ 
processes. The governing Mission Directive does not encompass responsibilities for the \\ 
oversight of reservists working NSAT missions or delineate Service Cryptologic Components' 
responsibilities. A highlight of the inspection was the meticulous tracking of sensitive SIGINT 
database accesses within several mission product lines. The OIG will track corrective actions; 

(U/ /FQUQ) Investigation of Alleged Improprieties at NSA Georgia (NSAG) 


(b)(3)- 3 I. 86-36 


(S. - -RLL 10 USA 


1 VbVi In 14 August 2 00Q. the NSA OIG completed an investigation into an \ \ 


allegation that the 

processed ITS, person communications. 


broil am at NSAG unlawfully intercepted and 


than] 


Our investigation involved Interviews of the complainant, more 


Kyitness interviews 


and the forensic analys is of almost 
records. We found no targeting of U.S. persons by| | 



(U , 4 H)U0k A ~ litio na!ly. the NSA OIG substantiated anallegation that an NSAG analyst, at the 
request of the n had queried a SIGINT raw traffic database on the seleetoKof a person in the 
United Slates. The person was a relative of a valid foreign intelligence target;; 


(b)(3)-P.L. 86-36 


(b)(1) 

(b)(3)-P.L. 86-36 


I OP skrRhk.COMlMMvOrOR^ 
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SOP SUCREI "COMi> - iT"NQroilN 


(1 • ) . , , ! n , Misuse of the U.S. SIGINT System (USSS) 
U- vl Kl 1. TO USA. PVL¥ 4 


ised the USSS to taruet 


a soldier within a U.S. Army 
vis wife, also a soldier Stationed! 


queried an NS A database for her 


Follow ing questions 


He 

torn his 

auditor, the soldier confessed his actions. After investigation by the unit substantiated the 
misuse, the soldier received rioti-judieial punishment. Through a 1 informed Code of Military 
Justice Field Grade Artide 15. the soldier's rank was reduced from Sergeant to Specialist; he was 
given 45 days ex tra duty and forfeited one half month s pay for two months (suspended for 180 
days). The unit has revoked the soldier's access to classified information. 


(b)(3)-P.L. 86-36 


(1) Congressional, IOB, and DNI Notifications 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(d)(3)-P.L. 86-36 


TiiUCl ,\T > 

NSA notified the Congressional Oversight Committees of t 

retention compliance problem 




NSA officials moved 

immediately to remedy the erro: 

* and implemented 


to ensure that additional FISA-de 


period lor i ISA 


would be sent only t< a repository that has the correct age-off 


Rrata. An 


ate 


the repositories into compliance was forwarded 
included as an addendum to this report. 

4 hi l'AI AM*-! 


t o explain remedial steps NS \ will take to bring 
Copies of the notifications are 


NS A notified the ( ongressiona! Oversight Committees ol 


journalists’ claims of NSA’s irresponsibility in executing its mission pursuant to E.O. 12333 or 
FISC Orders, in the letters. NS A provided factual data to refute the claims. 1 he notification is 
enclosed. 


(TG/VSU^P r 


NSA provided a notification and update on the handling of 


Business Records and Pen Register Trap and Trace data obtained under FISC Orders. Reviews 
conducted over the past se\eral months ha\ e unco\ ered inadequate attention to internal systems 
and systems architecture that resulted in a failure to fully comply with Court imposed procedures 
documented in the FISC Order. The notification describes several compliance matters and 
remediation actions that have been disclosed to the Court and Congressional Oversight 
Committees. The notification and End-to-End Review of Business Records FISA Report is 
enclosed. 


3. (U) Substantive Changes to the NSA/CSS Intelligence Oversight Program 

(U) Nothing to report. 

4, (U) Changes to NSA/CSS published directives or policies concerning 
intelligence, counterintelligence, or intelligence-related activities and the reason 
for the changes 


(l > Nothing to report. 


TOP SECP.F'IV'COMI^ j dxor 01 w 
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TOP SP-CRh'i/VCQMIK i NUl OllN 


5. (U) Procedures governing the activities of Department of Defense (DoD) 
intelligence components that affect U.S. persons (DoD Directive 5240.1-R, 
Procedure 15) Inquiries or Matters Related to Intelligence Oversight Programs 

(l : j Nothing to report. 


IQE S) f/hVi i. 'CUMiN'l "NOfORh r 
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MEMORANDUM FOR - .11 DIRECTOR. SEN ATI'. SELECT 

COMMITTEE ON IN I LLIGENCE 


SUBJECT: • U) Congi'es.-Jo ml Notification New York Times article “E-Mail 
Surveillance Renews Concerns in Cungress" - IN FORMATION 
MEMORANDUM 

(U) On 17 June 2009 Tin Ye w York Tunes published an article bv Janie- 
Risen and Eric Lichtblau entitled “E-Mail Surveillance Renews Concerns in 
Congress." The article^contains man rt ions that mak< it seem as if NSA 

is broadly irresponsible in executing its mission pursuant to Executive Order 
■ it Foreign Intelligence Surveillance Court (FISC) Orders. The opposite is 
true. 

i v /Ft >1 t > As Mm know and we hav< acknowledged. NSA has recen 
identified and reported compliance issues with FISC orders. However, the 
article's assertion that NSA has deliberately and illegally collected domestic 
communications of U.S. persons is patently false. The accusations are far 
afield of the compliaiKi a it ers wi have experienced which largely relate t< 
deficiencies in the way ' S.\ w-tems managed data that was lawfully 
collected. Moreover, tla ia t 1 hat the compliance issues have been id ntified. 
reported to the FISC andC tgresaion il overseers, and that steps were takei 
to remedy them testiiies to NSA’s commitment to oversight. 

D i While it is difficult to know exactly what the article's anonymous sources 
are referring to in regards to each of their claims, given the gross 
mischaracterizations of the article it is important to state for the record what 
we know to be true. 


• (3//31//HF) Early ia the article it states that in 2005 a former NSA 
analyst was trained on a program in which NSA routinely examined 
large volumes of Am- i icons - email messages without court warrants. 
Given the lack of contt %• provided relating to this claim, it is difficult 
to know what is actually alleged to have occurred. However, il this 
refers to the previous!’, well documented and publicly aired allegation 
nl David Faulk, th ations are false - a conclusion that NSA’s IG 
will soon report o i . 
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■n- - - ■,i*n A IM 11 . 


• (U) The article goes on to suggest that NSA is not up to the challenge 

of protecting the privacy rights of U.S. person communications that an 
encountered as a result of lawful collection of foreign intelligence. To 
the contrary, NSA lias robust minimization procedures and 
mechanism* in place to limit to the greatest possible extent the impact 
on privacy rights These procedures are subject to either approval of 
the Attorney General, in relation to collection pursuant to EO 12333. 
or to the FISC, in relation to collection pursuant to FISA. 


• 4S//SI//NT) Later, the rvides an illustration of a supposed 

compliance problem in which NSA’s attempts to target 1,000 emails 


mr r 

(b)(3)-50 DSC 3024(i) 
(b)(3).-1 8 USC 798- 
(b)(3)-P.L. 86-36 


__ji aiainsi those 1 .OOP nlu.-enut her 1,000 that, an* 


not intended; 



NSA frasempl yedsign and effort t 



These mitigation < Hi rt s inv olve continuous process improvements to 
prevent and/or detect ] H at the earliest possible point and the 


« (U// FOUO) The article also identifies a 30% threshold for the inclusion 
ofll.S. person u tion within NSA database* Thi no truth U 
this statement, as the existence of U.S. person information in NSA 
databases is limited not by a percentage number but by the NSA’s 
targeting practices that seek foreign intelligence only. 


* ii/'‘NF*Th< additional allegation that NSA has 44 ...improperly 
■ d the personal email of former IV : Bill Clinton 19 is an 
inaccurate portray al of at i event that dates from 1992. NSA’s records 
of the event demonstrate NSA’s commitment tot n and 

com pliance. 


(b)(3)-P.L: 86-36 


(b)(1) 

(b)(3)-50 USC 3024(i) 
(b)(3)-P.L. 86-36 


u ember 3 1992, an analyst wondering how 
n featg . .gie n actiiur to Bill Clinton’s election typed in 



There were probably very 
lew email- of any kind in there at that time, and there would nut 


—--H—---— 
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tn- t 'll UVII M > « »l ■ » . 

about Bill( lintoi in nediateiy "hitef the query Ivaffe eiiterea, ' 
the co-worl i sitting next to the analyst identified that this was 
a query on a l S. person. The analyst immediately realized that 
the query m s wrong and contrary to authorities. The matter 
was quick! (ported to NSA leadership and resulted in 
notifications outside of NSA pursuant to Executive branch 
guidelines. As a result of this incident the analyst's access was 
suspended while the analyst attended mandatory re training. 

(U) Although this activity occurred 17 years ago, we have used it 

in our oversight training, even in the last several years, as an 
illustrative example of queries that are inappropriate and must 
be reported and invest igated. This type of query remains as 
inappropriate today as it was then and will not be tolerated 
under any circumstances. 

<l’) NSA remains committed to providing transparency in these matters a 
promise made by the DIRNSA We would be pleased to meet with the 
Committee to address any concerns that may remain. 

'C 

JONATHAN E. MILLER 
Associate Director 
Legislative Affairs Office 



Copy Furnished: 

Minority Staff Director. Senate Select 
Committee on Intelligence 


-- 


— —— 



